| Vulnerability Name: | CVE-2013-4428 (CCN-88062) | ||||||||||||
| Assigned: | 2013-10-15 | ||||||||||||
| Published: | 2013-10-15 | ||||||||||||
| Updated: | 2018-11-15 | ||||||||||||
| Summary: | OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID. | ||||||||||||
| CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||||||
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2013-4428 Source: REDHAT Type: Third Party Advisory RHSA-2013:1525 Source: CCN Type: oss-sec Mailing List, Tue, 15 Oct 2013 20:56:57 +0200 CVE request for a vulnerability in OpenStack Glance Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20131015 CVE request for a vulnerability in OpenStack Glance Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20131015 Re: CVE request for a vulnerability in OpenStack Glance Source: BID Type: Third Party Advisory, VDB Entry 63159 Source: CCN Type: BID-63159 OpenStack Glance 'download_image' Policy Information Disclosure Vulnerability Source: CCN Type: BID-63851 OpenStack Glance '/var/log/glance' Insecure File Permissions Vulnerability Source: UBUNTU Type: Third Party Advisory USN-2003-1 Source: CONFIRM Type: Exploit, Third Party Advisory https://bugs.launchpad.net/glance/+bug/1235226 Source: CONFIRM Type: Exploit, Third Party Advisory https://bugs.launchpad.net/glance/+bug/1235378 Source: XF Type: UNKNOWN openstack-cve20134428-info-disc(88062) Source: CONFIRM Type: Patch, Third Party Advisory https://launchpad.net/glance/+milestone/2013.1.4 Source: CONFIRM Type: Patch, Third Party Advisory https://launchpad.net/glance/+milestone/2013.2 Source: CCN Type: OpenStack Glance Web Site OpenStack Glance Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4428 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||